Speed is easy. Cleared-to-ship is the hard part.
AI shortens the edit, but 2026 disclosure rules turn labeling, likeness consent, and rights clearance into a procurement question. Speed only counts if the asset is cleared — and a policy document does not clear anything. WorkFreq turns the policy into an enforced gate on the path content actually travels.
Disclosure is a gate, not a checkbox
An asset cannot be approved or delivered until it states how it was created, using a C2PA source type. Where that provenance is algorithmic, the database computes that a disclosure is owed and refuses the asset until an approved disclosure record exists. Article 50 binds from 2 August 2026.
Each asset carries one of five C2PA source types — from straight digital capture through to fully generated media. An upload that cannot say how it was made cannot reach approved or delivered.
The disclosure table is insert-only. Approving writes a second record that supersedes the first rather than editing it, so the declaration cannot be rewritten after the fact and the chain reads as an audit trail. Approval authority is a grant with a grantor, a timestamp and a revoke path — not a role name.
An asset whose provenance is undeclared is treated as blocked, not as clear, and an unresolved disclosure refuses delivery. The safe default is "do not ship," not "ship and hope."
Compliance is not legal advice; WorkFreq gives your team the enforced controls to operate the policy you set. Running a formal process? Send us the RFP →
Consent recorded, presence witnessed
A consent is recorded next to a witnessed presence stamp — the moment that person was actually at the camera — in an append-only event plane written only by privileged database triggers, which tenants can read but never write. It deliberately outlives the rows it describes, so removing a roster entry does not erase the record that a consent existed. The consent document itself is not copied in: a digest is stored instead, proving which document was in force without putting a second copy of someone's name and signature beyond the reach of an erasure request. Biometric identification is not used — that is a standing ruling, not a default setting.
The other two gates at the delivery doors
Disclosure is one clause of a single rights verdict, not a check bolted on beside it. That one verdict weighs embargo, licence window, expiry, talent conflict and the Article 50 hold together, and the same function answers both the reviewer's screen and the delivery doors — so what a reviewer is told and what the door enforces cannot drift apart. Around it sits row-level tenant isolation, with cross-tenant access refused at the database rather than filtered in the application. See the full governed pipeline →
Governance first, automation second — never the other way around
This version ships no agentic capability as a customer-facing feature. Nothing here publishes, edits, or delivers content on its own. We say that plainly because a compliance platform that overstates its automation has already failed the review it is asking you to pass.
Agentic capability is on the roadmap, and it will arrive inside the plane that is already in production rather than beside it: the same required provenance declaration, the same Article 50 disclosure with its separate declarer and approver, the same one rights verdict at the delivery doors, and the same append-only record a tenant can read but not write. That ordering is the point — the governance exists first, so adopting agentic capability will be a decision a client makes, never a default it inherits. We are not putting a date on it, because a dated promise is a claim and an undated direction is a position.
Before you ask
How do you handle EU AI Act Article 50 disclosure?
An asset must declare a C2PA source type before it can be approved or delivered. Where that provenance is algorithmic, the database computes that a disclosure is owed and clears it only on an approved record whose declarer and approver are separate entries. Fail-closed: unknown provenance blocks.
Do AI agents act on our content?
No. This version ships no agentic capability as a customer-facing feature — nothing publishes, edits, or delivers on its own. It is on the roadmap, and it will arrive governed by the compliance plane already in production.
Where are the rules enforced?
In the database, on the path content travels — not in app code that could be bypassed. One rights verdict answers both the reviewer's screen and the delivery doors, so display and enforcement cannot drift apart.
What is recorded about people in the content?
Consent plus a witnessed presence stamp, in an append-only plane that survives deletion of the rows it describes. The consent document is not copied in — a digest is, so erasure still reaches the original. Biometric identification is not used.